Data residency & storage
Where your data lives, what crosses borders, and why. We believe you should know exactly where your compliance data is stored — especially if you are ourselves subject to GDPR.
Last reviewed: May 2026
Where your data is stored
Core data stays in the EU. All compliance data, documents, evidence, and user records are stored in the EU West (Frankfurt, Germany) region. This data never leaves the EU unless you explicitly request export.
| Data type | Storage location | Notes |
|---|---|---|
| Customer account data (name, email, billing) | 🇪🇺 EU (Frankfurt, Germany) | Primary Supabase EU region |
| Compliance assessments and scores | 🇪🇺 EU (Frankfurt, Germany) | Never leaves EU region |
| Generated compliance documents (policies, DPIAs, AIAs) | 🇪🇺 EU (Frankfurt, Germany) | Row-level security per org |
| Evidence vault files | 🇪🇺 EU (Frankfurt, Germany) | Encrypted at rest (AES-256) |
| AI tool inventory and risk assessments | 🇪🇺 EU (Frankfurt, Germany) | Never leaves EU region |
| Vendor catalog and risk scores | 🇪🇺 EU (Frankfurt, Germany) | Never leaves EU region |
| Incident and audit logs | 🇪🇺 EU (Frankfurt, Germany) | Retained per your retention policy |
| Team member data (name, email, role) | 🇪🇺 EU (Frankfurt, Germany) | Linked to org, deleted on removal |
| Data Subject Request (DSR) records | 🇪🇺 EU (Frankfurt, Germany) | Encrypted; DPO access only |
| Transactional emails (alerts, reports) | 🇺🇸 US (Resend infrastructure) | Email metadata only; SCCs in place |
| Payment and billing data | 🇺🇸 US/EU (LemonSqueezy) | Merchant of Record — never touches our servers |
International data transfers
A small number of sub-processors operate outside the EU. For each, we have Standard Contractual Clauses (SCCs) in place under GDPR Chapter V.
| Recipient | Country | Transfer basis | DPA | Data shared |
|---|---|---|---|---|
| Resend (email delivery) | United States | Standard Contractual Clauses (EU SCCs) | Signed | Recipient email address, email content |
| LemonSqueezy (payments) | United States | Standard Contractual Clauses (EU SCCs) | Signed | Name, email, billing address |
| Cloudflare (CDN / DDoS) | United States | Cloudflare EU DPA / SCCs | Signed | IP addresses (ephemeral), request logs |
Our data commitments
EU-first storage
All compliance data stored in EU West (Frankfurt). We do not route EU data through US infrastructure.
Encryption at rest
All data encrypted at rest using AES-256. Database encryption key managed by Supabase.
Encryption in transit
All connections use TLS 1.2+. No unencrypted API endpoints.
No sub-processor surprises
We notify you 30 days before adding a new sub-processor that processes your personal data.
No AI training on your data
Your compliance data is never used to train AI models — ours or anyone else's. Document generation runs on static, deterministic templates; your content is never sent to a third-party AI provider.
Your right to export
You can export all your data at any time from Settings → Export. CSV, JSON, and PDF formats available.